
The challenge
Stellar is transparent by design. Every payment, every balance, and every contract entry is public and permanently indexed. For lending, that transparency is a dealbreaker: Existing lending protocols on Stellar expose everything. There is no way to: How might we let a user borrow on Stellar where the amounts stay private, solvency is proven in ZK on-chain, and a designated auditor can still verify the numbers?
The approach
Steal App solves this with four core primitives: 1. Poseidon2 Commitments for Position Hiding. Collateral amounts and debt amounts are never stored in the clear on-chain. Instead, the borrower stores Poseidon2([amount, salt]) — a commitment that hides the value. The salt is kept private by the borrower. 2. Client-Side ZK Proving (bb.js WASM). Every proof is built in the browser using Noir circuits compiled to WASM via Barretenberg's bb.js.
Next case study
HIMASIA EventHub — Campus Event & Ticketing Portal
PHP, Laravel, MySQL, Bootstrap